ms-365-mcp-server
Server Configuration
Describes the environment variables required to run the server.
| Name | Required | Description | Default |
|---|---|---|---|
| SILENT | No | Set to true or 1 to disable console output. | |
| LOG_LEVEL | No | Set logging level (default: 'info'). | |
| READ_ONLY | No | Set to true or 1 to start server in read-only mode, disabling write operations. | |
| ENABLED_TOOLS | No | Filter tools using a regex pattern (alternative to --enabled-tools flag). | |
| MS365_MCP_MAX_TOP | No | Hard cap for Graph $top/top on list requests (positive integer). Clamps larger values. | |
| MS365_MCP_ORG_MODE | No | Enable organization/work mode (alternative to --org-mode). Set to true or 1 to include Teams, SharePoint, etc. | |
| MS365_MCP_CLIENT_ID | No | Custom Azure app client ID (defaults to built-in app). Used with custom Azure AD app registration. | |
| MS365_MCP_MAX_ITEMS | No | Maximum number of items accumulated when fetchAllPages is true (positive integer, default 10000). | |
| MS365_MCP_MAX_PAGES | No | Maximum number of pages followed when fetchAllPages is true (positive integer, default 100). | |
| MS365_MCP_TENANT_ID | No | Custom tenant ID (defaults to 'common' for multi-tenant). Personal Microsoft accounts should set this to 'consumers'. | common |
| MS365_MCP_CLOUD_TYPE | No | Microsoft cloud environment: 'global' (default) or 'china' (21Vianet). | global |
| MS365_MCP_PUBLIC_URL | No | Public base URL for OAuth when behind a reverse proxy (browser-facing). | |
| MS365_MCP_REDACT_PII | No | Set to false or 0 to disable scrubbing of JWTs, Bearer headers, OAuth token fields, and email addresses from log messages (default: enabled). | |
| MS365_MCP_USE_KEYTAR | No | Set to 0, false, no, or off to skip the credential store and use a .cache-key file. Useful when keytar prompts or misbehaves. | |
| MS365_MCP_BODY_FORMAT | No | Set to 'html' to return email bodies as HTML instead of plain text (default: text). | |
| MS365_MCP_DISABLE_DCR | No | Set to true to disable OAuth Dynamic Client Registration (enabled by default in HTTP mode). | |
| MS365_MCP_OAUTH_TOKEN | No | Pre-existing OAuth token for Microsoft Graph API (Bring Your Own Token method). Bypasses interactive authentication. | |
| MS365_MCP_KEYVAULT_URL | No | Azure Key Vault URL for secrets management (e.g., MS365_MCP_CLIENT_ID, MS365_MCP_TENANT_ID, MS365_MCP_CLIENT_SECRET). | |
| MS365_MCP_CLIENT_SECRET | No | Client secret for your custom Azure AD app (optional for public apps). Used with custom Azure AD app registration. | |
| MS365_MCP_OUTPUT_FORMAT | No | Set to 'toon' to enable TOON output format for reduced token usage. | |
| MS365_MCP_ATTACHMENT_HOST | No | Interface the MS365_MCP_ATTACHMENT_PORT listener binds (alternative to --attachment-host; requires --attachment-port). | |
| MS365_MCP_ATTACHMENT_PORT | No | Serve the attachment route on its own listener on this port (alternative to --attachment-port; requires --enable-attachment-urls). | |
| MS365_MCP_ALLOW_PAGINATION | No | Set to 0, false, or no to disable multi-page following entirely. Default is enabled. | |
| MS365_MCP_TOKEN_CACHE_PATH | No | Custom file path for MSAL token cache. | |
| MS365_MCP_TRUST_PROXY_HOPS | No | Number of trusted reverse-proxy hops in HTTP mode (default 1). Set to 0 for raw socket peer IP. | |
| MS365_MCP_EXPECTED_USERNAME | No | Require local MSAL auth to use this Microsoft account username (case-insensitive). | |
| MS365_MCP_FORCE_WORK_SCOPES | No | Backwards compatibility for MS365_MCP_ORG_MODE. Set to true or 1 to enable organization mode. | |
| MS365_MCP_ATTACHMENT_URL_KEY | No | Required for server-minted attachment URLs. Signing key for minting attachment URLs. | |
| MS365_MCP_AUTH_CACHE_COMMAND | No | External executable wrapper for provider-neutral auth-cache storage. Replaces built-in keytar/file storage. | |
| MS365_MCP_ATTACHMENT_URL_BASE | No | Required for server-minted attachment URLs. Base URL for the attachment endpoint (e.g., http://m365-mcp:3000). | |
| MS365_MCP_RATE_LIMIT_DISABLED | No | Set to true or 1 to disable per-IP rate limiting in HTTP mode. Default is enabled. | |
| MS365_MCP_ATTACHMENT_URL_TTL_S | No | Optional TTL for attachment URLs in seconds (default 120, max 300). | |
| MS365_MCP_ATTACHMENT_URL_KEY_ID | No | Optional key ID for attachment URL signing (default 1). | |
| MS365_MCP_SELECTED_ACCOUNT_PATH | No | Custom file path for selected account metadata. | |
| MS365_MCP_MESSAGE_SIGNOFF_PREFIX | No | Signoff prepended to outgoing messages so recipients can tell they were agent-sent (e.g. '🤖'). | |
| MS365_MCP_MESSAGE_SIGNOFF_SUFFIX | No | Signoff appended to outgoing messages. | |
| MS365_MCP_EXPECTED_HOME_ACCOUNT_ID | No | Require local MSAL auth to use this exact MSAL homeAccountId. | |
| MS365_MCP_AUTH_CACHE_COMMAND_TIMEOUT_MS | No | Per-invocation timeout for MS365_MCP_AUTH_CACHE_COMMAND (default: 10000). |
Instructions
Guidance the server publishes about itself, which clients place ahead of the tool catalog so the model reads it before choosing anything.
This server publishes no instructions, or was last inspected before Glama recorded them.
Capabilities
Server capabilities have not been inspected yet.
Tools
Functions exposed to the LLM to take actions
| Name | Description |
|---|---|
No tools | |
Prompts
Interactive templates invoked by user choice
| Name | Description |
|---|---|
No prompts | |
Resources
Contextual data attached and managed by the client
| Name | Description |
|---|---|
No resources | |
This server cannot be deployed
Maintenance
ActivityActive
ResponsivenessNo issues